CVE-2021-42638: Command Injection
Published Feb 1, 2022
·Updated
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.
Affected Software
14 affected components
PrinterLogic Web Stack<19.1.1.13
PrinterLogic Web Stack=19.1.1.13
PrinterLogic Web Stack=19.1.1.13-sp2
PrinterLogic Web Stack=19.1.1.13-sp3-3
PrinterLogic Web Stack=19.1.1.13-sp9
Apple macOS
Linux Linux kernel
All of the following
Any of the following
PrinterLogic Web Stack<19.1.1.13
PrinterLogic Web Stack=19.1.1.13
PrinterLogic Web Stack=19.1.1.13-sp2
PrinterLogic Web Stack=19.1.1.13-sp3-3
PrinterLogic Web Stack=19.1.1.13-sp9
Any of the following
Apple macOS
Linux Linux kernel
Event History
Feb 1, 2022
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-42638?
CVE-2021-42638 is rated as critical due to its potential for pre-authentication remote code execution.
2
How do I fix CVE-2021-42638?
To fix CVE-2021-42638, upgrade your PrinterLogic Web Stack to version 19.1.1.14 or later.
3
What systems are affected by CVE-2021-42638?
CVE-2021-42638 affects PrinterLogic Web Stack versions up to and including 19.1.1.13 SP9.
4
What type of vulnerability is CVE-2021-42638?
CVE-2021-42638 is a remote code execution vulnerability caused by insufficient input validation.
5
Can CVE-2021-42638 be exploited remotely?
Yes, CVE-2021-42638 can be exploited remotely, allowing attackers to execute arbitrary code.